Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy
A security engineer is tasked with onboarding a new AWS account into Prisma Cloud for continuous security posture monitoring. Which of the following is the MOST secure and recommended method for granting Prisma Cloud the necessary permissions?
- AUtilizing an IAM role with a custom policy and an external ID for cross-account access.
- BConfiguring an EC2 instance role with an attached policy and sharing its ARN.
- CProviding Prisma Cloud with the AWS root account credentials for full access.
- DCreating an IAM user with programmatic access keys and attaching a custom policy.
Show answer & explanationAnswer & explanation
Correct answer: A. Utilizing an IAM role with a custom policy and an external ID for cross-account access.
Utilizing an IAM role with a custom policy and an external ID is the most secure and recommended method for cross-account access in AWS, as it avoids sharing long-lived credentials and enhances security through the external ID.
Why the other options are wrong
- B. Sharing an EC2 instance role ARN is not the standard or secure method for cross-account Prisma Cloud integration; it's designed for applications running on EC2 instances.
- C. Using root account credentials grants excessive permissions and is a severe security risk.
- D. IAM users with programmatic access keys introduce long-lived credentials, which are less secure than roles.
Prisma Cloud AWS Onboarding
The process of integrating an AWS account with Prisma Cloud for security monitoring, typically leveraging IAM roles for secure, granular access.
- IAM roles are preferred over IAM users for cross-account access.
- External ID enhances security by preventing the confused deputy problem.
- Least privilege principle should always be applied to assigned policies.
Memory trick: Securely connect your cloud, role up your permissions, and ID your external trust.